Legal

Privacy Policy

Last updated: 21 July 2026 · Applies to the Lampira app for iPhone, iPad and Mac (bundle space.lampira.app), the website lampira.space and the optional Lampira account & sync service. · Читать по-русски

In plain words

Lampira is local-first. Your notes, flashcards, mindmaps and attachments live on your device — and, if you turn on sync, in your own private iCloud. They never reach our servers, so we cannot read, share or lose them. Without an account we hold no data about you at all.

If you create an optional account, we process only your sign-in details and flashcard review events (which card was reviewed when, and the grade — never the content of your cards). Server logs are kept for 30 days for security. There are no ads, no trackers, no analytics SDKs, and we never sell data. AI features run on your device or connect directly to a provider you choose — never through us.

Contents
  1. Who we are (controller)
  2. Scope of this policy
  3. Local-first: what we never receive
  4. Data, purposes, legal bases, retention
  5. AI features and your data
  6. Recipients and processors
  7. International data transfers
  8. Security measures
  9. Your rights under the GDPR
  10. How to exercise your rights
  11. Complaints — supervisory authority
  12. Children
  13. Cookies
  14. Automated decision-making
  15. Changes to this policy
  16. Contact

1.Who we are (data controller)

The controller of personal data described in this policy, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the GDPR), is:

Daniel Adamowicz, sole developer of Lampira, established in the Republic of Lithuania.
Email for all privacy matters: support@lampira.space

Given the scale and nature of the processing, no data protection officer has been appointed (Article 37 GDPR does not require one). All requests are handled personally by the controller.

2.Scope of this policy

This policy covers:

It does not cover third-party services you choose to connect yourself (for example your own AI provider, your own iCloud, or a model running on your own computer). Those are governed by the terms and privacy policies of the respective providers.

3.Local-first: what we never receive

Lampira is built so that your study material does not depend on us. The following data is stored exclusively on your device and is never transmitted to, or accessible by, us:

The app can synchronise this content between your devices through your own private iCloud (Apple's CloudKit service). That sync runs entirely between your devices and your personal Apple account: the data is stored in your private iCloud database under your Apple ID and Apple's terms, and we have no access to it — we operate no servers in that path and receive nothing from it. Apple device backups are likewise your own arrangement with Apple.

Because this data never reaches our infrastructure, we cannot read it, hand it over, restore it or delete it for you. If you use Lampira without an account, we process no personal data about you at all (apart from short-lived technical server logs if you visit our website — see Section 4).

4.What we process, why, on what legal basis, and for how long

We process only the minimum data needed to run the optional account and sync service and to keep our server secure (Article 5(1)(c) GDPR — data minimisation).

Data categoryPurposeLegal basisRetention
Account data — email address (or the identifier and, where you choose it, the private relay email provided by Sign in with Apple), password hash (argon2; email accounts only), account creation and sign-in timestamps Creating and operating your account, authentication, sync across your devices, responding to account-related support Art. 6(1)(b) — performance of a contract (providing the service you request) Until you delete your account; then erased without undue delay, at the latest within 30 days
Flashcard review events — internal card/deck identifiers, review timestamps, your grade (e.g. again/good), FSRS scheduling state, device sync metadata. Never the text or content of your notes or cards Synchronising your review history and schedule between your devices Art. 6(1)(b) — performance of a contract Until you delete your account (deleted together with it)
Server logs — IP address, timestamp, requested endpoint, response status, user-agent string Security of the service: detecting and preventing attacks, abuse and technical faults Art. 6(1)(f) — our legitimate interest in keeping the service secure and available. You may object (Section 9) 30 days, then deleted automatically (retained longer only if needed as evidence of a specific security incident)
Support correspondence — your email address and the content of messages you send us Handling your question, request or rights request Art. 6(1)(b) / Art. 6(1)(f) — answering you; keeping a record of resolved requests As long as needed to resolve the matter, then up to 24 months for continuity of support, unless law requires longer
App access requests — the email address you write from Sending you the one invitation email you requested Art. 6(1)(a) — your consent, withdrawable at any time Until the invite is sent or you withdraw consent, whichever is earlier

We do not use the above data for advertising, profiling or analytics, and we do not enrich it with data from other sources. Where processing rests on consent (Article 6(1)(a) GDPR), you may withdraw consent at any time with effect for the future; withdrawal does not affect the lawfulness of processing before withdrawal (Article 7(3) GDPR).

5.AI features and your data

All AI features in Lampira are optional and are designed so that Lampira's servers are never in the data path:

When you connect a third-party AI provider, that provider processes the content you send it as described in its own privacy policy. You choose whether, when and what to send; we are not a party to that processing, we never proxy, store or see your prompts or the responses, and we receive no data about your use of those providers.

6.Recipients and processors

We do not sell personal data. We do not share personal data with advertisers, data brokers or analytics providers. The only recipients are:

7.International data transfers

Our server is located in the European Union, and we do not transfer personal data outside the European Economic Area.

If you use Sign in with Apple, Apple may process limited sign-in data outside the EEA (including in the United States). For such transfers Apple relies on its certification under the EU–U.S. Data Privacy Framework and, where applicable, on European Commission Standard Contractual Clauses, as described in Apple's privacy documentation.

8.Security measures

In line with Article 32 GDPR, we apply technical and organisational measures appropriate to the (deliberately small) risk profile of the service:

In the unlikely event of a personal data breach we will act in accordance with Articles 33 and 34 GDPR, including notifying the supervisory authority and, where required, affected users.

9.Your rights under the GDPR (Articles 15–22)

With respect to the personal data we process, you have the right to:

10.How to exercise your rights

We respond within one month of receiving your request. For complex or numerous requests this may be extended by up to two further months; we will tell you within the first month if so, with reasons (Article 12(3) GDPR). Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.

11.Right to lodge a complaint

If you believe our processing infringes the GDPR, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR), in particular in the EU member state of your habitual residence, place of work or the place of the alleged infringement. Our lead supervisory authority is:

Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of the Republic of Lithuania)
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
vdai.lrv.lt · ada@ada.lt

We would, of course, appreciate the chance to resolve any concern first — write to support@lampira.space.

12.Children

The Lampira account and sync service is not directed at children under 16, and we do not knowingly collect personal data from them. Under the Lithuanian Law on the Legal Protection of Personal Data, a child may consent to information society services from the age of 14; consistent with the cautious approach recommended in the guidance of the State Data Protection Inspectorate (VDAI), Lampira nevertheless applies a uniform minimum age of 16 for creating an account.

The app itself, used without an account, stores data only on the device and involves no collection of personal data by us. If you believe a child under 16 has created an account, contact support@lampira.space and we will delete it.

13.Cookies

The lampira.space website uses no analytics, no trackers and no third-party cookies. The only cookie we set is a single first-party session cookie on the sign-in hand-off page (the page that passes your sign-in from the browser to the app):

CookiePurposeTypeDuration
lampira_handoff Maintains your sign-in state for the few moments needed to hand the session over to the app First-party, strictly necessary Session — deleted when the browser session ends

Because this cookie is strictly necessary to provide a service you explicitly request, it is exempt from the consent requirement of Article 5(3) of Directive 2002/58/EC (ePrivacy) as implemented in the Lithuanian Law on Electronic Communications. That is why lampira.space has no cookie banner — there is simply nothing to consent to.

14.Automated decision-making and profiling

We carry out no automated decision-making producing legal or similarly significant effects (Article 22 GDPR) and no profiling. The FSRS spaced-repetition algorithm schedules your reviews, but it runs on your device, on your data, solely to help you study — it is a feature you control, not a decision about you.

15.Changes to this policy

We may update this policy when the service or the law changes. The "Last updated" date at the top always reflects the current version. For material changes — in particular any new category of data, new purpose or new recipient — we will give advance notice in the app or on lampira.space at least 14 days before the change takes effect and, where the change relies on consent, ask for it. Earlier versions are available on request.

16.Contact

Daniel Adamowicz — developer and data controller of Lampira, Republic of Lithuania.
Privacy, data protection and any other questions: support@lampira.space

This policy is provided in English and Russian. In case of any discrepancy, the English version prevails. Nothing in this policy limits the rights you have under the GDPR or Lithuanian law.